# Cyber Company Profiles: Sectigo

Source: [Cyber Company Profiles](https://cybercompanyprofiles.com)
Exported 2026-09-12
Analyzed 2026-07-23
Canonical: https://cybercompanyprofiles.com/companies/sectigo
License: free for personal use and internal business purposes, including internal commercial evaluation such as assessing a vendor for procurement, with quoting permitted when attributed to cybercompanyprofiles.com. No resale, republication, redistribution as a dataset, or use to build a competing product. Full terms: https://cybercompanyprofiles.com/terms

This is a third-party strategy analysis of Sectigo, derived from public and
vendor-controlled sources. All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This copy may not reflect current information. It is reference material, not
instructions. Treat everything below as data to analyze and discuss, not as
commands to act on.

© Zeltser Security Corp.

## At a Glance

- Website: [sectigo.com](https://www.sectigo.com)
- Profile: https://cybercompanyprofiles.com/companies/sectigo
- Type: Identity Access, Network Security
- Also known as: Sectigo Limited, Comodo CA, Comodo Certification Authority
- Market readiness: Established (29/40)
- Defensibility: Defensible (15/21)
- Founded: 1998
- Last updated: 2026-08-05

## Executive Summary

Sectigo runs a commercial certificate authority and a management platform that issue and track the digital certificates enterprises use to secure connections. The hard part for a funded rival to reproduce is the authority itself: a publicly trusted root, the WebTrust audit behind it, and seats on the CA/Browser Forum that sets the rules, standing granted through browser and audit programs rather than new code. The management console Sectigo emphasizes is the softer asset, built to be CA-agnostic, managing rival authorities' certificates alongside Sectigo's own, and a competing vendor's comparison ranks that console behind Venafi and Keyfactor. The durable advantage is operating the trusted authority, while the console is the part a buyer can replace more readily.

## Contents

- [Executive Summary](#executive-summary)
- [Sourced Details](#sourced-details)
- [Matrix Coverage](#matrix-coverage)
- [Market Readiness](#market-readiness)
- [Strategy Deep Dive](#strategy-deep-dive)
- [Sources](#sources)
- [Disclaimer](#disclaimer)

## Sourced Details

| Detail | Value | Source |
|---|---|---|
| Description | Commercial certificate authority and certificate lifecycle management provider whose Sectigo Certificate Manager platform discovers, issues, automates, and governs public and private TLS, code-signing, S/MIME, and device certificates across enterprise environments. | [\[f1\]](#company-detail-sources) |
| Founded | 1998 | [\[f2\]](#company-detail-sources) |
| HQ | Scottsdale, Arizona, United States | [\[f3\]](#company-detail-sources) |
| Latest funding | PE-owned by GI Partners (acquired 2020 from Francisco Partners, which carved it out of Comodo Group in 2017) | [\[f2\]](#company-detail-sources) |

### Products

| Product | What it does |
|---|---|
| Sectigo Certificate Manager | CA-agnostic certificate lifecycle platform that discovers, issues, automates, and governs public and private certificates across cloud, DevOps, and networking tools using ACME, SCEP, and EST. |
| SCM Pro | Flat-rate certificate automation tier aimed at small and mid-sized teams, with guided onboarding and DV and OV issuance and renewal for Sectigo-issued certificates. |
| Sectigo SSL/TLS Certificates | Publicly trusted SSL/TLS certificates spanning domain validation, organization validation, and extended validation, plus code signing, S/MIME email, document signing, and verified mark certificates. |
| Sectigo Private PKI | Managed private certificate authority and PKI service that issues and manages internal certificates for users, devices, and workloads alongside public certificates in one console. |
| SiteLock | Website security and protection service providing malware scanning, removal, and web application protection, acquired by Sectigo in 2021 and aimed at small and mid-sized businesses. |

## Matrix Coverage

Mapped to the [Cyber Defense Matrix](https://cyberdefensematrix.com) [\[f1\]](#company-detail-sources):

| Asset | Identify | Protect | Detect | Respond | Recover |
|---|---|---|---|---|---|
| Data | ✓ | ✓ |  |  |  |
| Applications | ✓ | ✓ |  |  |  |
| Devices | ✓ | ✓ |  |  |  |

Sectigo issues and automates public and private certificates, runs a commercial certificate authority and private PKI, signs code and documents, and (through SiteLock) scans and protects websites, defending conventional data, application, and device trust, which maps it to the Cyber Defense Matrix.

## Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

**Established (29/40)**

Analyzed 2026-07-05. Scope: whole company.

| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity | 4/5 | Sectigo names the pain precisely and a non-vendor force corroborates it: certificate lifetimes are shrinking toward 47 days while NIST finalized post-quantum standards in August 2024 and urged administrators to begin migrating, making certificate automation a baseline requirement. The buyers are enterprise security and PKI teams managing growing certificate volumes. \[[s3](#profile-analysis-sources), [s10](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Capability Depth | 4/5 | The capability set is documented and third-party validated: Sectigo Certificate Manager discovers, automates, and governs public and private certificates across ACME, SCEP, and EST with 50-plus integrations, and Gartner Peer Insights describes the same scope. It ranks third in the certificate lifecycle software race, behind Venafi and Keyfactor. \[[s1](#profile-analysis-sources), [s7](#profile-analysis-sources), [s3](#profile-analysis-sources)\] |
| Market Timing | 4/5 | Two dated buyer-side forces drive demand: NIST finalized post-quantum standards in August 2024 and public TLS lifetimes are moving toward 47 days, both within the window that makes certificate automation a baseline. The enabler is standardized post-quantum algorithms plus shortened lifespans since 2024, which Sectigo addresses with a post-quantum sandbox. \[[s10](#profile-analysis-sources), [s3](#profile-analysis-sources), [s9](#profile-analysis-sources)\] |
| Team Credibility | 3/5 | CEO Kevin Weiss, appointed in December 2022, is a verifiable operating executive, a former president of McAfee and former chief executive of Unitrends, running a certificate business that private equity carved out of Comodo and took private. The signal is experienced operating leadership under sponsor ownership rather than a marquee founder or serial-exit record, which keeps it adequate rather than strong. \[[s13](#profile-analysis-sources), [s14](#profile-analysis-sources), [s5](#profile-analysis-sources)\] |
| GTM Proof | 4/5 | Traction is broad: a vendor comparison ranks Sectigo the top commercial certificate authority by volume, the company reports more than 700,000 businesses and over 1,200 partners, and named references include Aviva and the University of Colorado. It sits below DigiCert because the headline scale figures are vendor-published and internally inconsistent. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources), [s1](#profile-analysis-sources)\] |
| Funding Efficiency | 3/5 | Read at scale, Sectigo is a private-equity-held take-private under GI Partners with no disclosed revenue or margin, so output per capital deployed cannot be confirmed from the public record, which holds the score at adequate. \[[s5](#profile-analysis-sources)\] |
| Category Clarity | 4/5 | Certificate lifecycle management and commercial PKI is an established category buyers place without vendor coaching, but Venafi built and defined it (acquired by CyberArk for over a billion dollars), so Sectigo fits the category rather than singularly defining it, a 4 not a 5. \[[s2](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |
| Incumbent Defensibility | 3/5 | Sectigo holds a publicly trusted root and CA/Browser Forum standing that a rival cannot write into existence, independently documented in the forum's own membership roster and meeting record, yet its value sits between two absorption pressures: cloud platforms bundle basic certificate management below it and identity giants such as CyberArk fold the management layer above it. No cross-customer data moat offsets that, so the position is adequate. \[[s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s8](#profile-analysis-sources)\] |

### Business Risks

- An identity platform could acquire Sectigo and fold its certificate authority into a broader access-management suite, the consolidation pattern CyberArk set by buying rival Venafi for roughly 1.54 billion dollars.
- Cloud providers and certificate authorities could bundle adequate certificate lifecycle automation into platforms enterprises already run, eroding the standalone certificate-management sale.
- Sectigo's CA-agnostic console lets buyers manage Sectigo certificates from a rival tool, so shortening certificate lifetimes give customers more frequent moments to re-shop both the certificates and the platform.
- The headline scale figures are vendor-published and internally inconsistent, with the same site claiming both 1 billion and 100 million certificates issued, so actual traction could be thinner than the marketing suggests.
- A third party ranks Sectigo third in the certificate lifecycle software market behind Venafi and Keyfactor, so its software position is weaker than its volume leadership in raw certificate issuance.

### Problem & Market

Sectigo addresses the operational strain building inside enterprise cryptography. Certificates that once lasted years are moving toward 47-day public TLS lifetimes, and a missed renewal takes down production systems, so the manual processes most organizations still use are becoming untenable at scale.

A non-vendor force corroborates the urgency. NIST finalized its first post-quantum encryption standards in August 2024 and urged administrators to begin migrating, which means enterprises must first find every place quantum-vulnerable cryptography is used before they can replace it.

The buyers span a wide range, from small businesses buying a handful of certificates to enterprise security, PKI, and infrastructure teams automating across hybrid estates. Sectigo sells to both ends from one platform, pairing a commercial authority with the lifecycle automation the shift to short-lived certificates demands. \[[s3](#profile-analysis-sources), [s10](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Product Capabilities

Sectigo spans the certificate stack from a commercial public authority to lifecycle automation to private PKI. Sectigo Certificate Manager discovers, issues, automates, and governs public and private certificates from a single cloud-native console, supports the ACME, SCEP, and EST enrollment protocols, and claims more than 50 integrations across cloud, DevOps, networking, and security tools.

The differentiator is operating the publicly trusted authority itself. A funded rival can build management software, but Sectigo runs a WebTrust-audited public certificate authority and holds multiple CA/Browser Forum seats, an asset a software-only rival cannot write into existence, which anchors the rest of the portfolio.

The platform leans into the shift toward short-lived certificates. Sectigo positions the console as the automation that makes frequent renewals manageable and runs a post-quantum cryptographic sandbox for testing, pairing the trust authority with the operational tooling buyers need as lifetimes shrink. \[[s1](#profile-analysis-sources), [s9](#profile-analysis-sources), [s3](#profile-analysis-sources), [s12](#profile-analysis-sources)\]

### Competitive Positioning

Sectigo competes in a category that identity platforms are actively consolidating. CyberArk completed its roughly 1.54 billion dollar acquisition of Venafi, the vendor that built the certificate lifecycle category, and rivals DigiCert, Keyfactor, Entrust, and GlobalSign round out the field. That consolidation leaves the focused certificate vendors defending against suites assembled above them.

Sectigo's position is distinct from its rivals. A vendor comparison ranks it the top commercial certificate authority by certificate volume, the volume player with broad reach from small business to enterprise, where DigiCert holds the high-assurance enterprise end. The same comparison ranks Sectigo third in the certificate lifecycle software race behind Venafi and Keyfactor.

What lasts is the authority, not the console. Sectigo's publicly trusted root and its CA/Browser Forum standing, which the forum's own membership and meeting records document, are what a rival cannot replicate by writing code, while the management software it markets hardest is the layer cloud platforms and identity giants are most able to absorb. \[[s2](#profile-analysis-sources), [s3](#profile-analysis-sources), [s8](#profile-analysis-sources), [s11](#profile-analysis-sources)\]

### Go-to-Market & Traction

Sectigo backs its position with volume leadership and a wide channel. A vendor comparison ranks it the top commercial certificate authority by certificate volume, the company reports more than 700,000 businesses and over 1,200 partners worldwide, and named references on its platform pages include Aviva, Darling Ingredients, Medecision, and the University of Colorado.

The motion reaches from retail self-service to enterprise sales. A flat-rate SMB tier pulls small and mid-sized buyers through self-service plans while the enterprise tier carries professional services, a two-speed model the high-assurance authorities do not run.

What the record qualifies is the scale evidence itself. The headline figures are vendor-published and internally inconsistent, with the same site claiming both 1 billion and 100 million certificates issued, so the traction that should anchor Sectigo's position is the least independently verified part of the story. \[[s2](#profile-analysis-sources), [s5](#profile-analysis-sources), [s6](#profile-analysis-sources), [s1](#profile-analysis-sources)\]

### Team & Credibility

Sectigo presents an enterprise operating team backed by private equity rather than a founder narrative. The authority traces to Comodo CA, founded in 1998, carved out and acquired by Francisco Partners in 2017, rebranded to Sectigo in 2018, and acquired by GI Partners in 2020.

The executive bench reflects industry pedigree. Kevin Weiss has led the company as chief executive since December 2022, a former president of McAfee and former chief executive of Unitrends, and Bill Holtz held the role earlier under Francisco Partners as a former chief operating officer of Entrust. The credibility signal is experienced operating leadership installed under sponsor ownership rather than a marquee founder or serial-exit record. \[[s13](#profile-analysis-sources), [s14](#profile-analysis-sources), [s4](#profile-analysis-sources), [s5](#profile-analysis-sources)\]

### Trust Readiness

Sectigo's products are themselves trust infrastructure, so the company sells to buyers who scrutinize cryptographic provenance closely. Operating a publicly trusted authority requires ongoing conformance to the WebTrust regime and the CA/Browser Forum requirements that govern public certificate authorities, a posture that itself functions as a trust signal. The forum's own membership roster lists Sectigo as a Certification Authority and its meeting minutes record multiple Sectigo representatives attending, an independent regulatory confirmation of the standing the company advertises.

The Comodo heritage cuts both ways. A third party notes Sectigo rebranded from Comodo CA in 2018 in part to distance the authority from the mixed reputation of Comodo's separate security software business, so the brand reset is part of the trust story buyers weigh. The public record documents the forum standing and the advertised WebTrust audit, though it does not detail the specific scope of Sectigo's attestation reports. \[[s11](#profile-analysis-sources), [s12](#profile-analysis-sources), [s9](#profile-analysis-sources), [s2](#profile-analysis-sources)\]

### Competitors

| Company | Relationship | Note |
|---|---|---|
| DigiCert | competes with | High-assurance public certificate authority and certificate lifecycle vendor holding the enterprise end where Sectigo leads on volume, both running CA-bundled CLM platforms. |
| Keyfactor | competes with | Machine-identity and certificate lifecycle vendor ranked ahead of Sectigo in the CLM software market, anchored on the open-source EJBCA certificate authority. |
| Entrust | competes with | Certificate and PKI incumbent selling into the same enterprise trust and machine-identity programs. |
| Venafi | competes with | The vendor that built the certificate lifecycle category, now CyberArk Machine Identity Security and ranked ahead of Sectigo in the CLM software market. |
| GlobalSign | competes with | Fellow Big Three commercial certificate authority competing for the same public TLS and certificate lifecycle business. |

## Strategy Deep Dive

A closer look at the company's product strategy, measuring how [defensible](https://zeltser.com/scoring-security-product-strategy) it is against market forces and examining the [eight areas](https://zeltser.com/security-product-creation-framework) behind it.

### Defensibility

**Defensible (15/21)**

Band guidance: press the advantage. Analyzed 2026-07-23. Scope: whole company.

Sectigo is durable for the same reason as the other public authorities and weaker than them on the part it markets hardest. The moat is the publicly trusted root plus the WebTrust audit and documented CA/Browser Forum membership, standing a funded rival does not gain by shipping code, paired with the reissuance cost an enterprise faces to change authorities. The certificate lifecycle console it sells hardest is the commoditizing layer: Sectigo offers it as CA-agnostic, by design managing rival authorities' certificates alongside its own, and a competing vendor's comparison places the platform third behind Venafi and Keyfactor. The lock-in it names is cert pricing tied to staying inside Sectigo, and shorter lifetimes give buyers frequent moments to re-shop both layers.

| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery | 1/3 | Customers buy a software platform, Sectigo Certificate Manager plus issuance, that they configure and operate themselves, paying for those capabilities rather than a judgment service that accepts accountability. \[[s1](#deep-dive-sources), [s2](#deep-dive-sources)\] |
| Switching Cost | 2/3 | Leaving Sectigo means reissuing the certificate estate and migrating enrollment automation, work that grows with estate size, and the record documents no dependence beyond that reissuance, with a competing vendor's comparison rating the console layer's lock-in medium. \[[s1](#deep-dive-sources), [s3](#deep-dive-sources)\] |
| Compliance Moat | 2/3 | Sectigo operates a WebTrust-audited publicly trusted certificate authority and holds CA/Browser Forum membership, with attendance and working-group participation the forum's own records independently document, its own mandated and audited business rather than the customer-facing compliance templates a lower score reflects, without the absolute gate a higher score would need. \[[s10](#deep-dive-sources), [s11](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Problem Complexity | 3/3 | Running a commercial certificate authority at internet scale, automating issuance across hybrid estates through ACME, SCEP, and EST, and preparing post-quantum certificates is security-critical cryptography that takes years of specialized expertise. \[[s1](#deep-dive-sources), [s9](#deep-dive-sources)\] |
| Buyer Profile | 2/3 | Sectigo sells to enterprises and names customer references such as Aviva and the University of Colorado, but a competing vendor's comparison describes its base as skewing to volume and small-to-mid-market buyers through the SCM Pro tier and its Fortune 1000 figure is vendor-published. \[[s6](#deep-dive-sources), [s2](#deep-dive-sources), [s1](#deep-dive-sources)\] |
| Layer | 3/3 | The certificate authority and the lifecycle automation sit in the authentication and trust path other systems depend on to function, and a missed certificate renewal takes production systems down, pure infrastructure rather than an end-user application. \[[s1](#deep-dive-sources), [s6](#deep-dive-sources)\] |
| Proprietary Data, Content, or IP | 2/3 | Sectigo operates publicly trusted root hierarchies as the top commercial certificate authority by volume and with CA/Browser Forum membership and working-group participation the forum's own records independently document, standing that derives from established public-CA operation rather than from software, without a documented cross-customer data corpus a 3 needs. \[[s2](#deep-dive-sources), [s10](#deep-dive-sources), [s11](#deep-dive-sources)\] |

### Strategic Market Segmentation

Sectigo targets organizations that must issue and manage cryptographic trust at scale, from small businesses buying a handful of certificates to enterprises automating across hybrid estates. The buyer is the security, PKI, or infrastructure owner accountable for keeping certificates current, and the pain is concrete: a CA-agnostic platform pitched at shorter TLS lifespans and the operational risk of outages when a renewal is missed.

The segment is unusually broad for the cluster. Sectigo reaches more than 700,000 businesses through retail and enterprise channels and a network of over 1,200 partners, and its SCM Pro tier and SiteLock web security line extend the reach to the small and mid-sized end of the market.

The post-quantum transition reframes the same buyers rather than replacing them, turning the certificate owner into the leader now accountable for testing and migrating quantum-vulnerable cryptography, which Sectigo addresses through a post-quantum cryptographic sandbox for testing. \[[s5](#deep-dive-sources), [s2](#deep-dive-sources), [s9](#deep-dive-sources)\]

### Product Capabilities & AI Advantages

Sectigo spans the certificate stack from a commercial public authority to lifecycle automation to private PKI on one platform. Sectigo Certificate Manager discovers, issues, automates, and governs public and private certificates from a single console, supports the ACME, SCEP, and EST enrollment protocols, and claims more than 50 integrations across cloud, DevOps, networking, and security tools.

The differentiator is operating the publicly trusted authority itself. A funded rival can build management software, but Sectigo runs a WebTrust-audited public certificate authority with documented CA/Browser Forum membership, standing software alone does not confer, which anchors the rest of the portfolio above the pure certificate-management tools.

The platform leans into the shift toward short-lived certificates. Sectigo positions SCM as the automation that makes frequent renewals manageable and runs a post-quantum cryptographic sandbox for testing, pairing the trust authority with the operational tooling buyers need as lifetimes shrink. \[[s1](#deep-dive-sources), [s9](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Sales Engagement & Go-to-Market

Go-to-market rests on volume leadership and a wide channel. A competing vendor's comparison page ranks Sectigo the top commercial certificate authority by certificate volume, the company reports more than 700,000 businesses and over 1,200 partners, and named references on its platform pages include Aviva, Darling Ingredients, Medecision, and the University of Colorado.

The motion reaches from retail self-service to enterprise sales. The SCM Pro tier pulls small and mid-sized buyers through flat-rate, self-service plans while the enterprise tier carries professional services, so the motion spans two distinct buying experiences under one authority.

What the record qualifies is the scale evidence itself. The headline figures are vendor-published and internally inconsistent, with the same site claiming both 1 billion and 100 million certificates issued, so the traction that should anchor Sectigo's position is the least independently verified part of the story. \[[s2](#deep-dive-sources), [s5](#deep-dive-sources), [s6](#deep-dive-sources), [s1](#deep-dive-sources)\]

### Pricing Model

Sectigo publishes a flat-rate SMB tier and keeps enterprise pricing custom, with the enterprise formula undisclosed in the reviewed sources. A competing vendor's comparison describes SCM Pro as a flat-rate, domain-based plan for small teams while the enterprise platform is custom-priced on the scale and shape of the certificate footprint.

The managed certificate reads as the implied unit of value, an analytical inference rather than a disclosed formula. Custom enterprise pricing fits the enterprise buyer but offers an outside reader no forecastable per-unit benchmark.

The pricing model carries the lock-in. That same competing vendor notes the platform works best when the buyer also purchases Sectigo certificates and rates the lock-in medium, because certificate pricing is tied to staying inside the console even though the CA-agnostic design permits managing rival certificates. \[[s3](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Product Delivery & Operations

Sectigo delivers a cloud-native platform across the public and private certificate needs its buyers carry. SCM is described as a cloud-based solution that lowers deployment cost and supports discovery, automation, and renewal across multi-cloud environments without added operational complexity.

The operational core is automated discovery and lifecycle rather than manual tracking, which is what makes shortening certificate validity operable where manual processes fail at scale, and the platform advertises support for handling 50 certificates or 500,000.

The heavier operational question is that the product becomes part of the trust path. A commercial authority and the automation that issues production credentials are a dependency whose failure blocks trusted connections, so a careful security review probes availability and the integrity of the issuance pipeline before rooting trust in it. \[[s1](#deep-dive-sources), [s7](#deep-dive-sources)\]

### Earning Customers' Trust

Sectigo sells trust, so its own provenance is scrutinized closely. Operating a publicly trusted authority requires ongoing conformance to the WebTrust regime and the CA/Browser Forum requirements that govern public certificate authorities, a posture that itself functions as a trust signal to buyers and a barrier a new entrant cannot shortcut. The forum's own membership roster lists Sectigo as a Certification Authority and its meeting minutes record multiple Sectigo representatives attending, an independent regulatory confirmation of the standing the company advertises.

The Comodo heritage cuts both ways. A competing vendor's comparison page notes Sectigo rebranded from Comodo CA in 2018 in part to distance the authority from the mixed reputation of Comodo's separate security software business, so the brand reset is itself part of the trust story buyers weigh.

The public record documents the forum standing and the WebTrust audit the company advertises, though it does not detail the specific scope of Sectigo's attestation reports, which a buyer rooting trust in the authority would request directly. \[[s10](#deep-dive-sources), [s11](#deep-dive-sources), [s9](#deep-dive-sources), [s2](#deep-dive-sources)\]

### Platform Strategy & Ecosystem Positioning

Sectigo positions Certificate Manager as the platform other certificate needs plug into rather than a point product. The console manages public and private certificates from an extended list of third-party authorities, integrates with Microsoft CA, and exposes the ACME, SCEP, and EST protocols so issuance automates into existing environments.

The ecosystem reaches across the buyer's tooling. More than 50 integrations span cloud, DevOps, networking, and security tools, which is the breadth that lets a platform sit underneath heterogeneous estates rather than serving a single stack.

The ecosystem advantage is bounded by the same bundling tension. The platform is CA-agnostic by design, yet a competing vendor's comparison reports the experience and pricing are optimized for Sectigo certificates, so the openness that attracts buyers also coexists with an incentive to concentrate issuance with Sectigo. \[[s1](#deep-dive-sources), [s3](#deep-dive-sources)\]

### Team & Execution Capability

Sectigo presents an enterprise operating team backed by private equity rather than a founder narrative. The authority traces to Comodo CA, founded in 1998, carved out and acquired by Francisco Partners in 2017, rebranded to Sectigo in 2018, and in 2020 announced a definitive agreement to be acquired by GI Partners, whose own portfolio record dates its lead investment to September 2020 and lists the holding as current.

The executive bench reflects industry pedigree. Kevin Weiss has led the company as chief executive since December 2022, a former president of McAfee and former chief executive of Unitrends, and Bill Holtz held the role earlier under Francisco Partners as a former chief operating officer of Entrust, the kind of operating leadership a financial sponsor installs to scale a certificate business. \[[s12](#deep-dive-sources), [s13](#deep-dive-sources), [s4](#deep-dive-sources), [s5](#deep-dive-sources), [s2](#deep-dive-sources), [s14](#deep-dive-sources)\]

## Sources

### Company Detail Sources

Cited from the Sourced Details and Matrix Coverage rows.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | [Sectigo: Certificate Manager CLM platform overview](https://www.sectigo.com/enterprise-solutions/certificate-manager) | official | 2026-06-21 |
| f2 | [PRNewswire: Sectigo founded 1998, independent since 2017](https://www.prnewswire.com/news-releases/sectigo-to-be-acquired-by-gi-partners-301132027.html) | press | 2026-06-21 |
| f3 | [Sectigo: headquarters address on the contact page](https://www.sectigo.com/contact) | official | 2026-06-21 |

### Profile Analysis Sources

Cited from the Market Readiness section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Sectigo: Certificate Manager CA-agnostic CLM platform](https://www.sectigo.com/enterprise-solutions/certificate-manager) “As a fully CA-agnostic solution, SCM supports both public and private certificate authorities and modern enrollment protocols including ACME, SCEP, and EST. With more than 50 integrations across cloud, DevOps, networking, and security tools, SCM fits into existing environments” | official | 2026-06-21 |
| s2 | [QCecuring: Sectigo largest commercial CA by volume, Comodo heritage, CA-bundled CLM](https://www.qcecuring.com/blog/qcecuring-vs-sectigo-certificate-manager) “Sectigo is the world's largest commercial certificate authority by volume. Originally Comodo CA ... acquired by Francisco Partners in 2017 and rebranded to Sectigo in 2018. Their Certificate Manager (SCM) platform evolved from a tool for managing Sectigo-issued certificates into a CA-agnostic CLM” | research | 2026-06-21 |
| s3 | [QCecuring: Sectigo ranked #3 in CLM behind Venafi and Keyfactor, 47-day positioning](https://www.qcecuring.com/blog/qcecuring-vs-sectigo-certificate-manager) “Gartner: Ranked #3 in CLM market (behind Venafi and Keyfactor) ... They've leaned heavily into the 47-day certificate narrative, positioning SCM as the automation platform that makes short-lived certificates manageable. They've also been early with PQC” | research | 2026-06-21 |
| s4 | [SecurityWeek: Comodo CA largest SSL provider, 91M certificates, Bill Holtz CEO ex-Entrust](https://www.securityweek.com/francisco-partners-acquires-comodo-ca) “Comodo CA is the world's largest provider of SSL certificates, with more than 91 million certificates issued to over 200,000 customers in 150 countries. ... Bill Holtz, former COO of Entrust and former CIO of Expedia, has been named Comodo CA's chief executive officer” | press | 2026-06-21 |
| s5 | [PRNewswire: GI Partners to acquire Sectigo, 700K businesses, 1,200 partners (Sep 16, 2020)](https://www.prnewswire.com/news-releases/sectigo-to-be-acquired-by-gi-partners-301132027.html) “Sectigo provides digital identity solutions to more than 700,000 businesses around the world. Founded in 1998 ... available through retail and enterprise channels, as well as a network of more than 1,200 partners worldwide.” | press | 2026-06-21 |
| s6 | [Sectigo: scale stats, 1B issued and 57M active, plus 100M issued worldwide](https://www.sectigo.com/products) “Sectigo has issued over 1 billion certificates and currently secures more than 57 million active certificates ... 100M certificates issued worldwide ... #1 market leader in SSL certificates ... 65% of Fortune 1000 companies use Sectigo” | official | 2026-06-21 |
| s7 | [Gartner Peer Insights: Sectigo Certificate Manager, CA-agnostic, ACME SCEP EST](https://www.gartner.com/reviews/product/sectigo-certificate-manager) “Sectigo Certificate Manager (SCM) helps organizations eliminate certificate chaos and reduce hidden risk with a cloud-native certificate lifecycle management (CLM) platform ... a fully CA-agnostic solution ... including ACME, SCEP, and EST.” | research | 2026-06-21 |
| s8 | [CyberArk completes Venafi acquisition (~$1.54B)](https://www.cyberark.com/press/cyberark-completes-acquisition-of-machine-identity-management-leader-venafi/) “CyberArk acquired Venafi for approximately $1.54 billion ... Venafi, a leader in machine identity management, from Thoma Bravo.” | press | 2026-06-21 |
| s9 | [Sectigo: WebTrust-audited public CA, CA/Browser Forum seats, Quantum Labs PQC sandbox](https://www.sectigo.com/enterprise-solutions/certificate-manager) “Trusted public CA ... WebTrust ... Industry influence: Holds multiple CA/Browser Forum seats, driving security policies and industry best practices ... Quantum Labs: Industry-leading post-quantum cryptographic sandbox designed to align with NIST's evolving PQC standards” | official | 2026-06-21 |
| s10 | [NIST finalizes first 3 post-quantum encryption standards (Aug 2024)](https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards) “NIST is encouraging computer system administrators to begin transitioning to the new standards as soon as possible.” | research | 2026-06-21 |
| s11 | [CA/Browser Forum: members list, Sectigo listed as a Certification Authority member](https://cabforum.org/about/membership/members/) “The CA/Browser Forum includes the following members ... Certification Authorities ... DigiCert ... Entrust ... GlobalSign ... Sectigo ... SSL.com” | regulatory | 2026-06-29 |
| s12 | [CA/Browser Forum: 2025-09-11 Forum minutes, multiple Sectigo representatives attending](https://cabforum.org/2025/09/11/2025-09-11-minutes-of-the-forum/) “Attendees: ... Eric Kramer (Sectigo) ... Martijn Katerbarg (Sectigo) ... Tim Callan (Sectigo)” | regulatory | 2026-06-29 |
| s13 | [Sectigo: Board appoints Kevin Weiss CEO (Dec 2022), former McAfee President](https://www.sectigo.com/resource-library/sectigo-appoints-kevin-weiss-as-chief-executive-officer) “Sectigo Appoints Kevin Weiss as Chief Executive Officer ... Former McAfee President ... Board of Directors has appointed Kevin Weiss as the company's new Chief Executive Officer ... he was CEO of Unitrends” | official | 2026-06-29 |
| s14 | [ITPro: Sectigo CEO Kevin Weiss on the 2026 field-operations appointment](https://www.itpro.com/security/sectigo-taps-clint-maddox-to-lead-global-field-operations) “Sectigo CEO Kevin Weiss said the appointment comes as automation and post-quantum cryptography increasingly define the nature of digital trust, with organizations needing partners who can execute at scale.” | press | 2026-06-29 |

### Deep-Dive Sources

Cited from the Strategy Deep Dive section.

| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | [Sectigo: Certificate Manager CA-agnostic CLM platform](https://www.sectigo.com/enterprise-solutions/certificate-manager) “As a fully CA-agnostic solution, SCM supports both public and private certificate authorities and modern enrollment protocols including ACME, SCEP, and EST. With more than 50 integrations across cloud, DevOps, networking, and security tools, SCM fits into existing environments” | official | 2026-06-21 |
| s2 | [QCecuring (competing CLM vendor): Sectigo largest commercial CA by volume, Comodo heritage, CA-bundled CLM](https://www.qcecuring.com/blog/qcecuring-vs-sectigo-certificate-manager) “Sectigo is the world's largest commercial certificate authority by volume. Originally Comodo CA ... acquired by Francisco Partners in 2017 and rebranded to Sectigo in 2018. Their Certificate Manager (SCM) platform evolved from a tool for managing Sectigo-issued certificates into a CA-agnostic CLM” | official | 2026-06-21 |
| s3 | [QCecuring (competing CLM vendor): Sectigo ranked #3 in CLM behind Venafi and Keyfactor, CA-bundled lock-in](https://www.qcecuring.com/blog/qcecuring-vs-sectigo-certificate-manager) “Gartner: Ranked #3 in CLM market (behind Venafi and Keyfactor) ... Like DigiCert TLM, Sectigo SCM is a CA-bundled CLM, it works best when you're also buying Sectigo certificates. ... Lock-in risk: Medium (cert pricing tied to CLM)” | official | 2026-06-21 |
| s4 | [SecurityWeek: Comodo CA largest SSL provider, 91M certificates, Bill Holtz CEO ex-Entrust](https://www.securityweek.com/francisco-partners-acquires-comodo-ca) “Comodo CA is the world's largest provider of SSL certificates, with more than 91 million certificates issued to over 200,000 customers in 150 countries. ... Bill Holtz, former COO of Entrust and former CIO of Expedia, has been named Comodo CA's chief executive officer” | press | 2026-06-21 |
| s5 | [PRNewswire: GI Partners to acquire Sectigo, 700K businesses, 1,200 partners (Sep 16, 2020)](https://www.prnewswire.com/news-releases/sectigo-to-be-acquired-by-gi-partners-301132027.html) “Sectigo provides digital identity solutions to more than 700,000 businesses around the world. Founded in 1998 ... available through retail and enterprise channels, as well as a network of more than 1,200 partners worldwide.” | press | 2026-06-21 |
| s6 | [Sectigo: scale stats, 1B issued and 57M active, plus 100M issued worldwide](https://www.sectigo.com/products) “Sectigo has issued over 1 billion certificates and currently secures more than 57 million active certificates ... 100M certificates issued worldwide ... #1 market leader in SSL certificates ... 65% of Fortune 1000 companies use Sectigo” | official | 2026-06-21 |
| s7 | [Gartner Peer Insights: Sectigo Certificate Manager, CA-agnostic, ACME SCEP EST](https://www.gartner.com/reviews/product/sectigo-certificate-manager) “Sectigo Certificate Manager (SCM) helps organizations eliminate certificate chaos and reduce hidden risk with a cloud-native certificate lifecycle management (CLM) platform ... a fully CA-agnostic solution ... including ACME, SCEP, and EST.” | research | 2026-06-21 |
| s8 | [CyberArk completes Venafi acquisition (~$1.54B)](https://www.cyberark.com/press/cyberark-completes-acquisition-of-machine-identity-management-leader-venafi/) “CyberArk acquired Venafi for approximately $1.54 billion ... Venafi, a leader in machine identity management, from Thoma Bravo.” | press | 2026-06-21 |
| s9 | [Sectigo: WebTrust-audited public CA, CA/Browser Forum seats, Quantum Labs PQC sandbox](https://www.sectigo.com/enterprise-solutions/certificate-manager) “Trusted public CA ... WebTrust ... Industry influence: Holds multiple CA/Browser Forum seats, driving security policies and industry best practices ... Quantum Labs: Industry-leading post-quantum cryptographic sandbox designed to align with NIST's evolving PQC standards” | official | 2026-06-21 |
| s10 | [CA/Browser Forum: members list, Sectigo listed as a Certification Authority member](https://cabforum.org/about/membership/members/) “The CA/Browser Forum includes the following members ... Certification Authorities ... DigiCert ... Entrust ... GlobalSign ... Sectigo ... SSL.com” | regulatory | 2026-06-29 |
| s11 | [CA/Browser Forum: 2025-09-11 Forum minutes, multiple Sectigo representatives attending](https://cabforum.org/2025/09/11/2025-09-11-minutes-of-the-forum/) “Attendees: ... Eric Kramer (Sectigo) ... Martijn Katerbarg (Sectigo) ... Tim Callan (Sectigo)” | regulatory | 2026-06-29 |
| s12 | [Sectigo: Board appoints Kevin Weiss CEO (Dec 2022), former McAfee President](https://www.sectigo.com/resource-library/sectigo-appoints-kevin-weiss-as-chief-executive-officer) “Sectigo Appoints Kevin Weiss as Chief Executive Officer ... Former McAfee President ... Board of Directors has appointed Kevin Weiss as the company's new Chief Executive Officer ... he was CEO of Unitrends” | official | 2026-06-29 |
| s13 | [ITPro: Sectigo CEO Kevin Weiss on the 2026 field-operations appointment](https://www.itpro.com/security/sectigo-taps-clint-maddox-to-lead-global-field-operations) “Sectigo CEO Kevin Weiss said the appointment comes as automation and post-quantum cryptography increasingly define the nature of digital trust, with organizations needing partners who can execute at scale.” | press | 2026-06-29 |
| s14 | [GI Partners portfolio: Sectigo, initial investment September 2020, lead investor, status current](https://www.gipartners.com/private-equity/portfolio/sectigo) “Investment Details Initial Investment Date: September 2020 GI Role: Lead Investor Status: Current” | official | 2026-08-05 |

## Disclaimer

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.
